Nora/Trust/HIPAA · BAA
Trust

HIPAA · BAA.

Nora handles protected health information for a living. Here's exactly what that means — what we collect, how we protect it, and the Business Associate Agreement that backs it.

Effective May 1, 2026

01 What HIPAA means for Nora

Home care agencies are covered entities. The operator they hire is a business associate. Nora is built that way from the ground up.

The Health Insurance Portability and Accountability Act of 1996, the HITECH Act of 2009, and their implementing regulations (the “HIPAA Rules”) set the federal standard for how protected health information is created, stored, transmitted, and disclosed by covered entities and their business associates.

When you use Nora, your agency remains the covered entity. Atlas AI, Inc. — the maker of Nora — acts as your business associate. We sign a Business Associate Agreement before you receive production access, and that agreement, together with the safeguards described below, governs every piece of PHI Nora touches.

02 Our role as a Business Associate

Atlas AI provides Nora as a service to your agency. In the course of doing so, Nora may receive, create, maintain, or transmit PHI on your agency's behalf — for the limited purposes of running your scheduling, chart, billing, communications, hiring, and compliance operations.

We do not use PHI for any purpose other than performing those services for you, except as expressly permitted by the BAA and the HIPAA Rules. We do not sell PHI. We do not use PHI to train models that serve other customers. We do not market to your patients.

If we ever change those rules, you will hear about it from us before it takes effect. Material BAA changes are sent in writing and require your written assent.

03 What PHI we handle

Depending on which Nora capabilities your agency has enabled, the operator may store, process, or transmit the following categories of information:

  • Client identifiers — name, date of birth, address, primary contacts, family relationships.
  • Clinical information — care plans, visit notes, medication schedules, mood and vitals observations, RN signatures.
  • Visit data — GPS-verified clock-ins and clock-outs, caregiver assignments, EVV-compliant logs.
  • Communications — texts, voice transcripts, and call recordings between Nora and clients, families, caregivers, and payers.
  • Documents — POA, advance directives, hospital discharges, payer correspondence, intake paperwork.
  • Financial information — invoice history, payment methods, settlement records.

Nora does not collect Social Security numbers from clients except where required for a specific payer enrollment, and we do not store full payment card numbers — payment methods are tokenized at our PCI-DSS Level 1 processor.

04 Safeguards

HIPAA requires administrative, physical, and technical safeguards. Here is what each looks like inside Nora:

CategoryWhat we do
Encryption — in transitTLS 1.3 for every connection. No unencrypted endpoints. HSTS preloaded on every Nora domain.
Encryption — at restAES-256 across all primary data stores. PHI fields additionally enveloped with per-customer keys.
Key managementGoogle Cloud KMS with strict separation of duties. Customer-specific keys rotate on a fixed schedule and on demand.
Access controlSSO + MFA enforced for all workforce members. PHI access is role-scoped, audited, and time-bounded.
Audit logsEvery read, write, and export of PHI is logged with actor, timestamp, and record identifier. Logs are immutable and retained for six years.
Backup & recoveryEncrypted point-in-time backups in a separate availability region. RPO ≤ 5 min. RTO ≤ 4 hr.

05 Workforce & access

Every Atlas employee or contractor who can be exposed to PHI signs a confidentiality agreement, completes HIPAA Privacy and Security training before access is granted, and re-trains annually. Access is provisioned through identity-managed groups; nothing is granted permanently.

Where Nora's agent reads PHI in the course of doing work — drafting a family message, generating an invoice, matching a caregiver — that access is scoped to the customer's tenant. Nora cannot read across tenants, and the underlying model providers we use do not receive identifying PHI.

06 Subprocessors

We use a small set of HIPAA-eligible subprocessors to run the service. Each has signed a BAA with Atlas AI, and each is bound to use PHI only on our instructions. The current list:

  • Google Cloud Platform — hosting, compute, storage, KMS.
  • Twilio— SMS & voice infrastructure (HIPAA-eligible).
  • Datadog — observability with sensitive-data redaction at the agent layer.
  • Stripe— payment tokenization & ACH (PCI-DSS Level 1, no PHI passed).
  • Foundation model providers — under enterprise zero-retention agreements; no training on customer data.

We give 30 days' notice before adding any new subprocessor that handles PHI, and we publish the updated list on this page.

07 Breach & incident response

We follow a written incident response plan. Suspected security incidents are triaged within one hour. Confirmed incidents involving PHI are escalated to the Privacy Officer immediately.

If a reportable breach occurs that affects your agency's PHI, we will notify you in writing without unreasonable delay and in no event later than 30 days after discovery, with the information you need to fulfill your own HIPAA notification obligations.

08 Signing the BAA

A BAA is required before any agency receives production access. We sign one with every customer — not just enterprise. Our standard form is short, plain-English where the law allows, and a redline-friendly Microsoft Word version is available on request.

  • Standard term — coterminous with your Order Form.
  • Return / destruction of PHI — within 30 days of termination, with audit log retained six years as required.
  • Indemnification — capped at the greater of fees paid in the prior 12 months or $1,000,000.
  • Subcontractors — must execute downstream BAAs no less protective than ours.

If your legal team has a preferred BAA form, send it to us.We will redline within five business days. We have not yet met a BAA we couldn't negotiate.

09 Privacy Officer

HIPAA requires every business associate to designate a Privacy Officer. Ours is reachable directly — not via a ticket queue.

Atlas AI, Inc.
Privacy Officer · San Francisco, CA
privacy@nora.care